7.5
CVSSv2

CVE-2011-0510

Published: 20/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote malicious users to execute arbitrary SQL commands via the oid parameter in an add_other action.

Vulnerable Product Search on Vulmon Subscribe to Product

awbs advanced webhost billing system 2.3.3

awbs advanced webhost billing system

awbs advanced webhost billing system 2.9.0

awbs advanced webhost billing system 2.7.5

awbs advanced webhost billing system 2.7.4

awbs advanced webhost billing system 2.5.1

awbs advanced webhost billing system 2.5.0

awbs advanced webhost billing system 2.2.1

awbs advanced webhost billing system 2.2.0

awbs advanced webhost billing system 2.0.3

awbs advanced webhost billing system 2.0.2

awbs advanced webhost billing system 2.7.1

awbs advanced webhost billing system 2.7

awbs advanced webhost billing system 2.8.3

awbs advanced webhost billing system 2.8.2

awbs advanced webhost billing system 2.7.0

awbs advanced webhost billing system 2.6.2

awbs advanced webhost billing system 2.3.2

awbs advanced webhost billing system 2.3.1

awbs advanced webhost billing system 2.1.0

awbs advanced webhost billing system 2.0.6

awbs advanced webhost billing system 2.9.1

awbs advanced webhost billing system 2.8.5

awbs advanced webhost billing system 2.8.4

awbs advanced webhost billing system 2.7.3

awbs advanced webhost billing system 2.7.2

awbs advanced webhost billing system 2.4.1

awbs advanced webhost billing system 2.4.0

awbs advanced webhost billing system 2.1.2

awbs advanced webhost billing system 2.1.1

awbs advanced webhost billing system 2.0.1

awbs advanced webhost billing system 2.0

awbs advanced webhost billing system 2.6.3

awbs advanced webhost billing system 2.5

awbs advanced webhost billing system 2.8.1

awbs advanced webhost billing system 2.8.0

awbs advanced webhost billing system 2.6.1

awbs advanced webhost billing system 2.6.0

awbs advanced webhost billing system 2.3.0

awbs advanced webhost billing system 2.2.3

awbs advanced webhost billing system 2.2.2

awbs advanced webhost billing system 2.0.5

awbs advanced webhost billing system 2.0.4

Exploits

AWBS 292 Blind SQL Injection 0day ============================================================================================= Dork: inurl:/cart?ca=add_other&oid= Date: 01-16-2011 Author: ShivX Contact: shivanx[at]gmail[dot]com Vendor: wwwawbscom Link: wwwawbscom/packagesphp?spt=10 (or demo site) Version: ...